CVE-2024-29155: Microchip RN4870

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is received, the device becomes incapable of completing the pairing process. A third party can inject a second PairReqNoInputNoOutput request just after a real one, causing the pair request to be blocked.

Affected products

  • Microchip RN4870: before 1.44 (fixed in 1.44)

Published 2024-10-16. Last modified 2026-06-17.